Web Application VAPT
A manual penetration test of your web application with proof-of-concept evidence and a retest after you fix.
Fixed fee · GST incl.
₹29,999
Scope, price and timeline published on every engagement page
Every identity in your cloud account reviewed against what it actually uses, with over-permissioned roles tightened safely.
Delivered in
10 working days
Revisions
One round, included
Ownership
Yours from day one
Overview
Permissions accumulate. A developer needed production access for one incident in 2023 and still has it. A CI role was given administrator rights because the correct policy was fiddly to work out. We pull the access analyser and CloudTrail data, compare granted permissions against what each identity has actually used over 90 days, and write least-privilege policies to replace the broad ones. Nothing is tightened blindly: every change is proposed, reviewed with you, and applied where it will not break a working system.
Deliverables
Outcomes
A compromised key gives an attacker far less than it does today
Departed staff and dormant credentials are found and removed
A repeatable quarterly review your team can run without us
Process
Collect
identity inventory and activity logs are gathered and analysed
Compare
granted permissions measured against real usage per identity
Propose
tightened policies drafted and reviewed with the owning teams
Apply
changes rolled out in agreed batches with rollback ready
These are collected in the technical brief that opens in your dashboard the moment payment clears. The clock starts when they arrive, not before.
Answers
That is why we use 90 days of real usage data and roll out in batches. Anything ambiguous is flagged rather than guessed at.
Yes, with the equivalent identity services. Mention your provider at checkout.
Only with your written approval, batch by batch. Nothing is revoked unilaterally.
This is engineering work, not a physical product — nothing ships and there is no stock to run out of. Delivery is to the working days stated above, into systems you control, and the refund terms set out what happens if we miss the date.
Booked alongside
A manual penetration test of your web application with proof-of-concept evidence and a retest after you fix.
Fixed fee · GST incl.
₹29,999
The technical controls and evidence collection an SOC 2 Type II audit needs, set up before the observation window starts.
Fixed fee · GST incl.
₹44,999
A practical gap assessment against India DPDP Act 2023, covering consent, retention, notices and breach procedure.
Fixed fee · GST incl.
₹22,999
We find the credentials committed to your repositories, rotate them, and set up scanning so it stops happening.
Fixed fee · GST incl.
₹12,999
GST included
₹18,999
Capacity open this month
No discovery calls to find out a number, no statements of work that take three weeks to sign. Pick the engagement that matches the problem and we assign the engineers.